Data Privacy & Security
Document version 2.0 — Last updated September 21, 2026
1. Overview
Smart Assistant is a Zoho CRM sidebar extension that provides unified visibility across a contact’s CRM profile, Zoho Books financial records, Zoho Desk support tickets, and an optional AI-generated strategic summary. It runs entirely inside Zoho CRM, either as a Related List widget on the contact page or as a view-page button that opens in an in-CRM popup.
This document describes how data is handled throughout the extension’s operation, including the limited cases in which data leaves your Zoho organization.
2. Authorization & Access
Smart Assistant does not ask users for Zoho credentials and does not run its own login, password, or token-collection flow. Access is granted through a Zoho CRM Connection that your organization’s administrator creates and authorizes inside Zoho CRM (Setup → Developer Hub → Connections).
2.1 How It Works
- Your Zoho administrator installs Smart Assistant and creates the Connection in your CRM organization.
- The administrator is shown Zoho’s official consent screen and approves the read-only scopes listed below.
- Zoho stores and manages the resulting authorization within Zoho. Smart Assistant never receives the tokens.
- When a user opens a contact, the widget calls Zoho through that Connection and renders whatever data the user is already permitted to see in Zoho.
Because authorization lives inside Zoho, it is admin-controlled: administrators can review, re-scope, or revoke it at any time from the Connections screen, and access follows each user’s existing Zoho permissions.
2.2 Scope of Access
| Scope | Purpose |
|---|---|
ZohoCRM.modules.READ | Read contact and account data from the CRM |
ZohoBooks.contacts.READ | Read customer/contact records in Zoho Books |
ZohoBooks.invoices.READ | Read invoices (overdue status and balances) from Zoho Books |
ZohoBooks.payments.READ | Read payment records from Zoho Books |
ZohoBooks.settings.READ | Read organization details to resolve the Zoho Books organization |
Desk.tickets.READ | Read support ticket history from Zoho Desk |
Desk.contacts.READ | Read contact data embedded in Desk tickets |
All requested scopes are read-only. Smart Assistant never creates, updates, or deletes CRM, Books, or Desk records.
3. Data Flow Architecture
Business data lives in Zoho and is read from Zoho. The only data that reaches Smart Assistant’s infrastructure is the context needed to produce an optional AI summary.
┌────────────────────────── Zoho CRM (in-CRM widget) ──────────────────────────┐
│ │
│ Smart Assistant widget / button ── Zoho Connection (read-only) ──► Zoho │
│ (Related List + view-page popup) APIs │
│ │ (CRM/Books/ │
│ │ HTTPS Desk) │
└────────────────────┼────────────────────────────────────────────────────────┘
│
│ viewing context only (for the AI summary)
▼
┌────────────────────────┐ HTTPS ┌────────────────────────┐
│ Smart Assistant │──────────►│ AI model provider │
│ backend (AI summary) │ │ (Gemini by default) │
└────────────────────────┘ └────────────────────────┘
3.1 Step-by-Step Data Flow
- User opens a contact in Zoho CRM → the Smart Assistant widget or button loads in the CRM UI.
- The widget reads data through the Connection — CRM contact and account details, Books invoices/payments, and Desk tickets — directly via Zoho’s APIs.
- Data is rendered in the browser inside Zoho. Smart Assistant’s servers are not involved in reading this data.
- Optional AI summary: to generate the strategic summary, the widget sends the contact context it is currently displaying to our backend, which forwards it to the configured AI provider and returns the summary text.
- Nothing is persisted beyond a short-lived in-memory cache (see §5).
3.2 What Is NOT Stored
- ✗ No Zoho credentials, access tokens, or refresh tokens are received or stored in the Connection-based flow
- ✗ CRM contact data is never written to disk on our servers
- ✗ Financial records are never stored after the response is sent
- ✗ Support tickets are never persisted
- ✗ No data is sold or shared with advertising networks, analytics providers, or data brokers
4. Data Sent to Our Backend
Our backend serves the extension’s pages and provides one functional endpoint: the AI summary.
4.1 AI Summary Endpoint
| Aspect | Detail |
|---|---|
| Endpoint | POST /api/summary/analyze (tokenless — no Zoho credentials are accepted) |
| What is sent | The contact context the user is currently viewing: contact fields (name, email, phone, account, lifecycle stage, last activity), account details, a summary of financial status (overdue totals/counts, recent payments), and open support tickets |
| Purpose | Solely to generate the AI strategic summary shown in the widget |
| Retention | Not persisted. Held only in an in-memory cache for 15 minutes, then evicted; cleared on restart |
| Rate limits | 30 requests/minute per IP; 200 KB request cap |
4.2 In-Memory Cache
Smart Assistant uses an in-memory TTL cache
(MemoryCache) so an unchanged summary is not regenerated
on every page load:
- What is cached: AI-generated summary text only (not raw CRM/Books/Desk data)
- Cache duration: 15 minutes by default
- Scope: process memory only — never written to disk
- Eviction: entries expire automatically; the cache is cleared on server restart
5. Storage & Retention
| Data Type | Stored? | Retention |
|---|---|---|
| CRM contact details | ✗ Not stored | Rendered live in the browser; discarded |
| Financial records (Books) | ✗ Not stored | Rendered live in the browser; discarded |
| Support tickets (Desk) | ✗ Not stored | Rendered live in the browser; discarded |
| AI-generated summaries | Cached in memory | 15 minutes, then evicted; never written to disk |
| Operation logs | Rotating logs | Rotated at ~5 MB; retention is configurable |
| Anonymous usage counters | Aggregated | Daily aggregate counts; no customer content |
In the Connection-based flow there is no token store, so there is no stored credential data to retain or delete. Customers who previously used the legacy standalone linking mode (superseded by the Connection and not used by Marketplace installations) can have their encrypted token entry removed by disconnecting or by contacting support.
6. Third-Party Services
Smart Assistant relies on a small number of service categories:
| Category | Role | Data |
|---|---|---|
| Zoho | CRM, Books, Desk APIs and the Connection authorization | All business data stays within Zoho; the Connection is bound to your organization and its data center |
| AI model provider | Generates the optional strategic summary | Receives the viewing context described in §4.1; used only to produce the response |
| Cloud hosting provider | Runs the backend that serves pages and runs the AI summary | Hosts the service, logs, and anonymous usage counters |
6.1 AI Model Provider
The AI summary is generated through a third-party AI model API. The default provider is Google Gemini; the provider is configurable by the operator (other OpenAI-compatible providers can be selected). The provider receives only the contact context described in §4.1 and returns generated text. Data sent to the provider is not used by us for any purpose other than producing the summary.
If no AI provider is configured, the AI summary feature is disabled and no data leaves our backend.
6.2 Zoho
Smart Assistant communicates with the Zoho CRM, Zoho Books, and Zoho Desk APIs provided to your organization, and with Zoho’s authorization service for the Connection. Your data remains in your Zoho organization and its data center; Smart Assistant does not copy it elsewhere.
6.3 No Other Third Parties
Smart Assistant does not use advertising networks, tracking pixels, third-party analytics SDKs, or data brokers.
7. Data Processing & GDPR Compliance
7.1 Lawful Basis
Smart Assistant processes Zoho data on behalf of the organization’s administrators and users, under the legitimate interest of providing business intelligence within the existing CRM workflow. The extension:
- Processes data only when explicitly triggered by the user viewing a contact
- Processes only the minimum data needed for the AI summary requested
- Retains nothing beyond the current session and the 15-minute in-memory cache
Where Smart Assistant processes personal data at the direction of a customer organization, the customer acts as data controller and Smart Assistant as processor.
7.2 User Rights
| Right | How It’s Handled |
|---|---|
| Access | All data is displayed in the widget at the moment of access; we hold no stored copy to request |
| Rectification | Data is read from Zoho directly — edit it in Zoho to see changes reflected |
| Erasure | Remove the extension / delete the Connection; the AI summary cache expires within 15 minutes |
| Data Portability | Data lives in Zoho — use Zoho’s export features |
| Restrict processing | Disable the AI summary (no provider configured) or remove the extension |
7.3 To Remove All Data
- Uninstall Smart Assistant or delete its Connection in Zoho CRM (Setup → Developer Hub → Connections) — this revokes the organization’s authorization.
- Any cached summary expires automatically within 15 minutes (or immediately on server restart).
- Aggregate usage counters and operation logs age out per §9.
8. Security Measures
| Area | Measure |
|---|---|
| Authorization | Zoho CRM Connection with read-only scopes — no password collection, no credentials handled by us |
| Transport | TLS 1.2+ (HTTPS) for all communications |
| Least privilege | Every requested scope is read-only; access follows the user’s existing Zoho permissions |
| Input validation | API inputs are validated; request size is capped |
| Abuse protection | Per-IP rate limiting on the AI summary endpoint |
| HTTP security | Standard security headers applied; widget HTML is served no-cache |
| Isolation | Backend runs as a managed container with minimal privileges |
| Logging | No tokens, payloads, or business data written to logs |
9. Logs & Usage Counters
9.1 Operation Logs
Our servers keep standard operation logs for reliability and security monitoring:
- Logged: request method, URL path, HTTP status, duration, IP address, user-agent, and a random request ID
- Not logged: request/response bodies, the contact context, financial amounts, support ticket content, or any credentials
- Rotation & retention: files rotate at ~5 MB; retention is configurable, and older archive files are pruned automatically
Logs may contain an IP address and user-agent as part of a standard access record — no other personal data is recorded.
9.2 Anonymous Usage Counters
To understand load and cost, we keep aggregate daily counters: the number of AI summary requests and provider calls, the provider name, token counts, latency, and failure counts. These counters contain no customer content and no identifiers — they are totals, not per-user records.
10. Your Rights & Contact
To exercise a data right, ask a privacy question, or request deletion of any of the limited data described above:
- Extension: Smart Assistant for Zoho CRM
- Publisher: Integmia LLC
- Website: www.integmia.org
- Email: contact@integmia.org
We aim to respond to data requests promptly and will confirm what (if anything) we hold and what action we have taken.